Vulnerability index

Browse CVEs

1,208 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness XML External Entity (XXE)CWE-611 × clear
Rational Team Concert HIGH 8.1
CVE-2017-1103

IBM Team Concert (RTC) is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remot…

Patch available
Fix from $1,950 2017-05-10
Websphere Cast Iron Solution HIGH 8.6
CVE-2016-9691

IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when …

Patch available
Fix from $1,950 2017-05-05
Urbancode Deploy HIGH 8.1
CVE-2017-1149

IBM UrbanCode Deploy (UCD) 6.0, 6.1, and 6.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when proces…

Mitigation only
Fix from $1,950 2017-04-25
Modified Ecommerce Shopsoftware CRITICAL 10.0
CVE-2017-8110

www.modified-shop.org modified eCommerce Shopsoftware 2.0.2.2 rev 10690 has XXE in api/it-recht-kanzlei/api-it-recht-kanzlei.php.

Mitigation only
Fix from $2,300 2017-04-25
Peoplesoft Enterprise Peopletools MEDIUM 6.5
CVE-2017-3548EPSS 51%

Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions…

Patch available
Fix from $1,600 2017-04-24
Fireware MEDIUM 5.3
CVE-2017-8056EPSS 5%

WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox…

Fix: after 11.2.1
Fix from $1,600 2017-04-22
Formatting Objects Processor HIGH 7.3
CVE-2017-5661

In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed S…

Fix: after 2.1
Fix from $1,950 2017-04-18
Batik HIGH 7.3
CVE-2017-5662

In Apache Batik before 1.9, files lying on the filesystem of the server which uses batik can be revealed to arbitrary users who send maliciously form…

Fix: after 1.8
Fix from $1,950 2017-04-18
Jackson Dataformat Xml HIGH 8.6
CVE-2016-7051

XmlMapper in the Jackson XML dataformat component (aka jackson-dataformat-xml) before 2.7.8 and 2.8.x before 2.8.4 allows remote attackers to conduct…

Fix: 2.7.8+
Fix from $1,950 2017-04-14
Mx Aopc Server MEDIUM 5.0
CVE-2017-7457

XML External Entity via ".AOP" files used by Moxa MX-AOPC Server 1.5 result in remote file disclosure.

No fix yet
Fix from $1,600 2017-04-14
Integrated Remote Access Controller Firmware CRITICAL 9.8
CVE-2015-7273

Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.

Fix: after 2.20.20.20
Fix from $2,300 2017-04-10
Ignite MEDIUM 5.9
CVE-2016-6805

Apache Ignite before 1.9 allows man-in-the-middle attackers to read arbitrary files via XXE in modified update-notifier documents.

Fix: after 1.8
Fix from $1,600 2017-04-07
Curam Social Program Management CRITICAL 9.1
CVE-2016-6111

IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when pr…

Patch available
Fix from $2,300 2017-03-31
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-9707

IBM Jazz Foundation is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote a…

Patch available
Fix from $1,950 2017-03-31
Zimbra Collaboration Suite CRITICAL 9.8
CVE-2016-9924

Zimbra Collaboration Suite (ZCS) before 8.7.4 allows remote attackers to conduct XML External Entity (XXE) attacks.

Fix: after 8.7.3
Fix from $2,300 2017-03-29
Debian Linux HIGH 7.5
CVE-2016-10149EPSS 5%

XML External Entity (XXE) vulnerability in PySAML2 4.4.0 and earlier allows remote attackers to read arbitrary files via a crafted SAML XML request o…

Fix: after 4.4.0
Fix from $1,950 2017-03-24
Usb Pratirodh CRITICAL 9.8
CVE-2017-6895

USB Pratirodh allows remote attackers to conduct XML External Entity (XXE) attacks via XML data in usb.xml.

No fix yet
Fix from $2,300 2017-03-23
Access Manager MEDIUM 5.5
CVE-2016-5748

External Entity Processing (XXE) vulnerability in the "risk score" application of NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.…

Mitigation only
Fix from $1,600 2017-03-23
Access Manager MEDIUM 5.5
CVE-2016-5749

NetIQ Access Manager 4.1 before 4.1.2 HF 1 and 4.2 before 4.2.2 was parsing incoming SAML requests with external entity resolution enabled, which cou…

Mitigation only
Fix from $1,600 2017-03-23
Junos Space MEDIUM 6.5
CVE-2016-4931

XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.

Fix: after 15.2
Fix from $1,600 2017-03-20
Webex Meetings Server MEDIUM 6.5
CVE-2017-3811

An XML External Entity vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to have read access to part of the …

Mitigation only
Fix from $1,600 2017-03-17
Qradar Security Information And Event Manager HIGH 8.1
CVE-2016-9724

IBM QRadar 7.2 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attack…

Patch available
Fix from $1,950 2017-03-07
Pysaml2 CRITICAL 9.0
CVE-2016-10127

PySAML2 allows remote attackers to conduct XML external entity (XXE) attacks via a crafted SAML XML request or response.

Patch available
Fix from $2,300 2017-03-03
Pdf Plugin MEDIUM 5.9
CVE-2017-6344

XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.

No fix yet
Fix from $1,600 2017-02-27
Rational Rhapsody Design Manager HIGH 8.1
CVE-2016-8974

IBM Rhapsody DM 4.0, 5.0 and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML dat…

Patch available
Fix from $1,950 2017-02-23
Eparakstitajs 3 HIGH 7.8
CVE-2017-6055

XML external entity (XXE) vulnerability in eParakstitajs 3 before 1.3.9 and eParaksts Java lib before 2.5.13 allows remote attackers to read arbitrar…

Fix: after 1.3.8
Fix from $1,950 2017-02-17
Identity Server HIGH 7.5
CVE-2016-4312EPSS 6%

XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote aut…

Patch available
Fix from $1,950 2017-02-17
Integration Bus CRITICAL 9.1
CVE-2016-9706

IBM Integration Bus 9.0 and 10.0 and WebSphere Message Broker SOAP FLOWS is vulnerable to a denial of service, caused by an XML External Entity Injec…

Patch available
Fix from $2,300 2017-02-15
Openpyxl HIGH 8.2
CVE-2017-5992

Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.

Patch available
Fix from $1,950 2017-02-15
Liebert Sitescan Web CRITICAL 9.8
CVE-2016-8348

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Li…

Fix: after 6.5
Fix from $2,300 2017-02-13